io/mongo/parser.py in Eve (aka pyeve) before 0.7.5 allows remote attackers to execute arbitrary code via Code Injection in the where parameter.
References
Link | Resource |
---|---|
https://github.com/pyeve/eve/commit/f8f7019ffdf9b4e05faf95e1f04e204aa4c91f98 | Patch Third Party Advisory |
https://github.com/pyeve/eve/issues/1101 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2018-03-14 12:29
Updated : 2024-02-04 19:46
NVD link : CVE-2018-8097
Mitre link : CVE-2018-8097
CVE.ORG link : CVE-2018-8097
JSON object : View
Products Affected
python-eve
- eve
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')